CVE-2023-54337
Unknown Unknown - Not Provided
Denial of Service via Password Field Overflow in Sysax Multi Server

Publication date: 2026-01-13

Last updated on: 2026-01-13

Assigner: VulnCheck

Description
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-13
Last Modified
2026-01-13
Generated
2026-06-16
AI Q&A
2026-01-14
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sysax multi_server 6.95
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2023-54337 is a denial of service vulnerability in Sysax Multi Server version 6.95. It occurs because the application does not properly validate the administrative password input field. An attacker with high privileges can input 800 bytes of repeated characters into the password field, causing the application to crash and disrupt server functionality. [1, 2]

Impact Analysis

This vulnerability can cause the Sysax Multi Server application to crash, resulting in a denial of service. This disrupts server functionality and availability, potentially affecting any services relying on this server until it is restarted or fixed. [1, 2]

Detection Guidance

This vulnerability can be detected by attempting to reproduce the denial of service condition locally on the Sysax Multi Server 6.95 application. A proof-of-concept involves generating a string of 800 repeated characters (e.g., 800 'A's) and pasting it into the administrative password field in the application settings. Specifically, you can create a file with 800 'A' characters using a command like `python -c "print('\x41' * 800)" > long_password.txt`, then copy the content to clipboard and paste it into the password field under Manage Server Settings β†’ Administrative Settings β†’ Configure. Saving this triggers the crash, confirming the vulnerability. Since this is a local vulnerability, network detection commands are not applicable. [2]

Mitigation Strategies

Immediate mitigation steps include restricting local administrative access to trusted users only, as exploitation requires high privileges and user interaction. Avoid pasting or entering excessively long strings (800 bytes or more) into the administrative password field. Monitor and limit access to the Sysax Multi Server administrative interface. Additionally, check for any vendor patches or updates addressing this issue and apply them once available. [1, 2]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54337. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart